SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Apple Critical Security Updates January 2022

Apple Critical Security Updates January 2022

Apple critical security update Jan 2022 has released security updates for multiple products. A total of 16 vulnerabilities were addressed. Exploiting some of these security flaws could allow an attacker to take control of an affected system.

Jan 27, 2022By Rinu K3 min read

Apple critical security update Jan 2022 has released security updates for multiple products. A total of 16 vulnerabilities were addressed. Exploiting some of these security flaws could allow an attacker to take control of an affected system.

The release also includes patches for two critical zero-day bugs exploited by attackers in the wild. These vulnerabilities can be tracked as CVE-2022-22587 and CVE-2022-22594. They affect macOS, iOS, iPadOS, and Safari browsers. Endpoints that have not been patched are advised to deploy patches ASAP using any patch management tool.

Apple critical security update Jan 2022 update for macOS includes fixes for 16 vulnerabilities that could allow an attacker to execute arbitrary code with kernel advantage, gain access to restricted files, bypass privacy preferences, gain elevated privileges, corrupt kernel memory, etc. Therefore, a total of 4 vulnerabilities have been fixed in Apple Safari. In brief, successful exploitation of these vulnerabilities will allow attackers to conduct arbitrary code execution, sensitive information report, cross-site scripting attacks.

Zero-Day (CVE-2022-22587)

This January’s security update fixed a critical zero-day memory corruption vulnerability actively exploited in the wild. It exists in IOMobileFrameBuffer(a kernel extension) component of macOS, iOS and iPadOS. Hence, the vulnerability allows an attacker to execute random code with kernel privileges. The vulnerability is reported by Security researchers Meysam Firouzi and Siddharth Aeri.

Zero-Day (CVE-2022-22594)

Another critical zero-day vulnerability in the Safari browser is also fixed in this January’s security update. It exists in the WebKit component of the Safari browser for macOS, iOS, and iPadOS. The flaw is due to a cross-origin issue in the IndexDB API, which web browsers use to manage a NoSQL database of JSON objects. However, the vulnerability allows an attacker to track user browsing activity and identities in real-time. The vulnerability is reported by Security researchers Martin Bajanik of FingerprintJS.

Apple Security Updates Summary for January 2022:

SanerNow VM and SanerNow PM detect these vulnerabilities and automatically fix them by applying security updates. To conclude, use SanerNow and keep your systems updated and secure.

Featured Posts

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026

Open Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers
Secpod_VEX_Studio For Open-Source Vulnerability Management

CVE Research

Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers

A human-guided path from SBOM and vulnerability data to reviewable OpenVEX statements

Sep 2, 2026

Open Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution
Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

CVE Research

Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

Sep 1, 2026

Apple Critical Security Updates January 2022 | SecPod